CVE-2026-82928
Received Received - Intake

Hardcoded SSH Public Key Backdoor in mH-DEVELOPER

Vulnerability report for CVE-2026-82928, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in versionΒ 3.0.30

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
f&f_filipowski mh-developer to 3.0.30 (exc)
mh-developer smart_home_module 3.0.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1242 The device includes chicken bits or undocumented features that can create entry points for unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, allowing root login via key authentication. An attacker with the matching private key can gain full system access through SSH, even after factory reset.

Detection Guidance

Check for the presence of the hardcoded SSH public key in /root/.ssh/authorized_keys on the device. Use commands like 'cat /root/.ssh/authorized_keys' or 'ls -la /root/.ssh/' to inspect the file. Verify if the SSH daemon allows root login via key authentication by checking configuration files like /etc/ssh/sshd_config for 'PermitRootLogin' settings.

Impact Analysis

An attacker could exploit this to gain root access to your smart home system, potentially controlling heating, lighting, sockets, valves, and other connected devices without authorization.

Compliance Impact

This vulnerability allows unauthorized root access to the device, potentially exposing sensitive data processed or stored by the smart home module. Compliance with GDPR could be impacted due to unauthorized data access or processing, while HIPAA compliance may be affected if the device handles protected health information. The hardcoded SSH key persists even after factory resets, making it difficult to ensure data protection measures remain effective.

Mitigation Strategies

Update the mH-DEVELOPER module to version 3.0.30 or later to remove the hardcoded SSH key. If updating is not immediately possible, isolate the device from untrusted networks, disable SSH access if not required, or restrict SSH access to trusted IP addresses. Note that the key persists through factory resets, so remounting the file system may be necessary to fully remove it.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82928. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart